CVE-2026-96524 PUBLISHED

MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF

Assigner: WPScan
Reserved: 23.09.2026 Published: 26.09.2026 Updated: 26.09.2026

The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.

Product Status

Vendor Unknown
Product MCP Server for WordPress
Versions Default: unaffected
  • affected from 0 to 1.8.2 (excl.)

Credits

  • Raphael P. Cigana finder
  • WPScan coordinator

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE